It's really not much different than walking around outside. You can walk in an unlocked retail store and it's okay, but if you walk into your neighbors bedroom it's not okay.
The crime isn't circumventing the locks. It's accessing what you don't have the right to access.
Is this that makes me think attempts to codify law on some blockchain is a doomed exercise most of the time.
I.e., if instead of an individual case, you could generate a million people who all tried to do every potential variation of breaking the law in that way, then what would the curve of the resulting judgements look like?
What matters is what you knew, what you should have known, what you could be expected to know, what you were told, what you observed, what you were thinking, what actions you took, and why you did it, etc.... and how all of these things line up with your local laws which will vary to a degree.
If you walked into the place confused because it wasn't clear what was a home and what was a business, that might be a valid way to demonstrate a lack of intent. But it wouldn't be because of zoning, it would be because of it way it appeared to you.
Let's instead talk about legal liability, and how corporations seek to discharge it in their delivery of products/services.
If I'm programming a political auto-dialer, there are rules about which numbers it's legally allowed to call, and which numbers it legally cannot. It can't call people's cell-phones, for example. If I don't want to get the people who buy one of these things in trouble (and then get sued by them), I have to program this device to follow these rules.
In such a case, it's not a matter of resolving the mens rea from committing such an act anyway; it's a question of how to avoid getting into a situation where my motivations (or the motivations of the purchaser) could ever possibly come into question. I don't want to come into court with a defense; I want to be bulletproof from being brought into court.
So, now, an analogy: if I'm programming a lifelogging-drone-as-a-service that people pay to follow them around all the time they're in "public space"—which, from what I recall, includes commercial spaces without access restrictions, e.g. retail shops, but does not include private residences—then what rules must I program this drone to follow about "what constitutes a public space", to avoid me (or a customer) ever being brought into court on charges of surveilling private property? (It's okay if such rules are next-to-impossible to resolve from the limited sensory data + local regulatory databases the drone has access to. The point isn't to construct such a drone; just to speak of more cut-and-dry case replacement for a human actor.)
To your example: You can buy drones today that will follow people around. The person who uses it is generally responsible for using it to film legally.
You know how a politician might hire a PR firm to produce a "day in the life of" documentary about them? Part of the PR firm's job would be to handle any negotiation of the local legal terrain required to get filming rights for locations, and likeness rights for other people appearing in the film. If they couldn't get such rights, it would also be part of their job to inform the customer of what things they now can't film, so that the customer could either make the choice to just leave some parts of their day un-filmed; or to re-arrange their schedule so that only legally-filmable events are on the roster for that day.
A hypothetical "camera drone as a service", in my mind, would be that, but handled mostly by an AI, maybe with OnStar-like interactive support if you get into an edge-case. (Again, it's a stupid idea! It's a thought-experiment, not a viable startup. :)
There are many services where part of the service you're paying for, is the service provider's expertise in navigating the local legal landscape in their own regulatory domain of expertise. In fact, that's entirely the point of some services: anyone can do their own accounting in a technical sense, but you pay an accountant because they know how to do your accounting in a way that complies with all your local regulations.
So, again: if one of the legal requirements of the CDaaS service is to automatically avoid (or at least not-surveil) any private property—then what would the rule for that look like?
Changing the technology from 35mm film to VHS Camcorder to AI powered drone doesn't make a difference. Adding abstractions between the lens and the operator makes no difference. If your organization films with cameras, it should make sure it does so legally.
> So, again: if one of the legal requirements of the CDaaS service is to automatically avoid (or at least not-surveil) any private property—then what would the rule for that look like?
If you have determined that you need to "avoid private property" in order to comply with the law, then the rule you'd want to implement is "don't film private property".
tldr: AT&T has an account status page that, for mobile devices, did not require any authorization. Something like /status?phone=8367492738 and you see the account data for that phone. It was guarded by a password if you navigated to it on a desktop/laptop, but it was unsecured if you navigated to it with a mobile device.
He spoofed the user agent string to make his laptop say it was a phone (this is extremely common, there is a button in your browser to do this in one click, and the spec that defines UA string specifically says not to use it for authorization for this exact reason), and dumped the account details from every url.
Despite these being pages publicly accessible on the open internet, he went to jail for years for unauthorized access under the CFAA
Well, I mean, that and (I'm sure) the fact that he was a notorious asshole and the authorities would rather make an example out of him than out of a more sympathetic defendant